Edit the file:/etc/sysconfig/iptables
The file content is as follows:
* Filter
: Input accept [0: 0]
: Forward accept [0: 0]
: Output accept [0: 0]
: RH-Firewall-1-INPUT-[0: 0]
-A input-J RH-Firewall-1-INPUT
-A forward-J RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT-I lo-J accept
-A RH-Firewall-1-INPUT-p icmp -- ICMP-type any-J accept
-An RH-Firewall-1-INPUT-P 50-J accept
-An RH-Firewall-1-INPUT-P 51-J accept
-A RH-Firewall-1-INPUT-p udp -- dport 5353-D 224.0.0.20.- J accept
-A RH-Firewall-1-INPUT-p udp-m udp -- dport 631-J accept
-A RH-Firewall-1-INPUT-p tcp-m tcp -- dport 631-J accept
-A RH-Firewall-1-INPUT-M state -- State established, related-J accept
-A RH-Firewall-1-INPUT-M state -- state new-m tcp-p tcp -- dport 389-J accept
-A RH-Firewall-1-INPUT-M state -- state new-m tcp-p tcp -- dport 22-J accept
-A RH-Firewall-1-INPUT-J reject -- reject-with ICMP-host-prohibited
Commit
When a new rule is specified, add the rule according to the preceding content.